A plugin is an add-on package for Claude Code. Some plugins bring MCP servers, which are external tools Claude can connect to. Plugin validation now also reads the plugin's MCP server files: .mcp.json, plus any ./*.json files that plugin.json lists under mcpServers. It does not follow symlinks (shortcut files that point somewhere else), and it refuses files above a size limit.
http:// or ws:// addresses to any host other than the local machine
header values that look like real credentials, matched against known token patterns or by how random the value looks on auth-style headers
lists used where settings objects are expected
a byte-order mark (BOM, an invisible marker at the start of a file)
too many server files
Why
The credential warning says why it matters: everything shipped in a plugin can be read by everyone who installs it. Plugin authors now hear about leaked secrets, unencrypted connections and broken server entries before they publish.
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared…